Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 05 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::destroyFiles of the file innopacks/restapi/routes/panel-api.php of the component Files Endpoint. This manipulation causes path traversal. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | yushine InnoShop Files Endpoint panel-api.php destroyFiles path traversal | |
| First Time appeared |
Yushine
Yushine innoshop |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:yushine:innoshop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Yushine
Yushine innoshop |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-05T20:15:10.144Z
Reserved: 2026-08-05T14:05:45.834Z
Link: CVE-2026-18959
No data.
No data.
No data.
OpenCVE Enrichment
No data.